Even if nothing is officially published from the authors at the time writing up this thread, it appears there is a critical security vulnerability within PhotoPost vbGallery 2.4.1, SQL injection type.
It's strongly encouraged to disable the plugin waiting for further news in the source link below, this may be a false warning but also a real one.
Sources:
My site was hacked - PhotoPost Community Forum Hacked - Need Some Assistance - vBulletin Community Forum